This is related to:
https://community.atlassian.com/t5/Bitbucket-questions/Is-there-a-way-to-disable-commits-from-unknown-users-on-a/qaq-p/624451
When a user has a improperly configured email on their PC, they can push commits that show up as "unknown" or "this user cannot be mapped to an Atlassian account".
Knowing who just pushed a commit is dependent on the person pushing the commit telling you they are the ones who pushed the commit. They must either tell you in person or properly configure their email before pushing the commit. Otherwise they can configure random information and push a commit that shows up as a unknown user.
My main issue is this can also be used by malicious people to push commits from "unknown" users and we can't tell who's machine or key was compromised.
We have a lot of commits from unknown users. While we think we've been able to verify most of them, we aren't certain they are all authorized commits.
In 2017 (see article) it was said there was no way to disallow this from happening. Are there any better options today? Are their any Atlassian workflows that can be adopted to prevent commits from unknown users.